Patentable/Patents/US-6549638
US-6549638

Methods for evidencing illicit use of a computer system or device

PublishedApril 15, 2003
Assigneenot available in USPTO data we have
Inventorsnot available in USPTO data we have
Technical Abstract

A computer is provided with software that looks for certain activities that may be illicit (e.g. processing of a graphic file corresponding to a banknote). If such an activity is detected, tracer data detailing the activity is generated and secretly stored. in the computer. If the computer is later searched or seized, the tracer data can be recovered and employed as evidence of the computer's use, e.g. in counterfeiting.

Patent Claims
24 claims

Legal claims defining the scope of protection, as filed with the USPTO.

1

1. A method for robustly evidencing illicit use of a computer system, the system having associated therewith at least one data processor and at least one non-volatile data store, the method comprising: receiving a signal indicating possible use of a system component for an illicit activity; in response to receipt of said signal, storing forensic tracer data in at least one of said non-volatile data stores; the method further including obfuscating said storage of said forensic tracer data so as to make detection thereof more difficult; wherein the obfuscating includes appending the forensic tracer data to an existing file having other contents not related to forensic tracer data.

2

2. The method of claim 1 wherein the obfuscating includes appending by inserting the forensic tracer data in a file's properties rather than file's contents.

3

3. A method for robustly evidencing illicit use of a computer system, the system having associated therewith at least one data processor and at least one non-volatile data store, the method comprising: receiving a signal indicating possible use of a system component for an illicit activity; in response to receipt of said signal, storing forensic tracer data in at least one of said non-volatile data stores; the method further including obfuscating said storage of said forensic tracer data so as to make detection thereof more difficult; wherein the storing includes storing without use of a file system normally employed by said computer system for file storage, wherein the forensic tracer data storage is not listed in a file listing produced by said file system.

4

4. A method for robustly evidencing illicit use of a computer system, the system having associated therewith at least one data processor and at least one non-volatile data store, the method comprising: receiving a signal indicating possible use of a system component for an illicit activity; in response to receipt of said signal, storing forensic tracer data in at least one of said non-volatile data stores; the method further including obfuscating said storage of said forensic tracer data so as to make detection thereof more difficult; wherein the obfuscating includes queuing the forensic tracer data in RAM for later storage, and later storing the data in said non-volatile store, wherein program tracing tools will not note an immediate write of said forensic tracer data to the non-volatile store.

5

5. A method for robustly evidencing illicit use of a computer system, the system having associated therewith at least one data processor and at least one non-volatile data store, the method comprising: receiving a signal indicating possible use of a system component for an illicit activity; in response to receipt of said signal, storing forensic tracer data in at least one of said non-volatile data stores; the method further including obfuscating said storage of said forensic tracer data so as to make detection thereof more difficult; wherein the obfuscating includes converting a deadwood file to use as a storage repository for said forensic tracer data.

6

6. A method for robustly evidencing illicit use of a computer system, the system having associated therewith at least one data processor and at least one non-volatile data store, the method comprising: receiving a signal indicating possible use of a system component for an illicit activity; in response to receipt of said signal, storing forensic tracer data in at least one of said non-volatile data stores; the method further including obfuscating said storage of said forensic tracer data so as to make detection thereof more difficult; wherein the obfuscating includes converting a duplicate file to use as a storage repository for said forensic tracer data.

7

7. A method for robustly evidencing illicit use of a computer system, the system having associated therewith at least one data processor and at least one non-volatile data store, the method comprising: receiving a signal indicating possible use of a system component for an illicit activity; in response to receipt of said signal, storing forensic tracer data in at least one of said non-volatile data stores; the method further including obfuscating said storage of said forensic tracer data so as to make detection thereof more difficult; wherein the obfuscating includes converting a long-unused file to use as a storage repository for said forensic tracer data.

8

8. A method for robustly evidencing illicit use of a computer system, the system having associated therewith at least one data processor and at least one non-volatile data store, the method comprising: receiving a signal indicating possible use of a system component for an illicit activity; in response to receipt of said signal, storing forensic tracer data in at least one of said non-volatile data stores; the method further including obfuscating said storage of said forensic tracer data so as to make detection thereof more difficult; wherein the obfuscating includes append the forensic tracer data to an application help file.

9

9. A method for robustly evidencing illicit use of a computer system, the system having associated therewith at least one data processor and at least one non-volatile data store, the method comprising: receiving a signal indicating possible use of a system component for an illicit activity; in response to receipt of said signal, storing forensic tracer data in at least one of said non-volatile data stores; the method further including obfuscating said storage of said forensic tracer data so as to make detection thereof more difficult, later performing an integrity check of the obfuscated forensic tracer data, and repairing any damage found.

10

10. A method for robustly evidencing illicit use of a computer system, the system having associated therewith at least one data processor and at least one non-volatile data store, the method comprising: receiving a signal indicating possible use of a system component for an illicit activity; in response to receipt of said signal, storing forensic tracer data in at least one of said non-volatile data stores; the method further including obfuscating said storage of said forensic tracer data so as to make detection thereof more difficult, and replicating obfuscated storage of said forensic tracer data at several storage locations.

11

11. A method for robustly evidencing illicit use of a computer system, the system having associated therewith at least one data processor and at least one non-volatile data store, the method comprising: receiving a signal indicating possible use of a system component for an illicit activity; in response to receipt of said signal, storing forensic tracer data in at least one of said non-volatile data stores; the method further including obfuscating said storage of said forensic tracer data so as to make detection thereof more difficult; wherein the computer system has an operating system including a registry database, and the method includes storing the forensic tracer data in said registry database.

12

12. A method for robustly evidencing illicit use of a computer system, the system having associated therewith at least one data processor and at least one non-volatile data store, the method comprising: receiving a signal indicating possible use of a system component for an illicit activity; in response to receipt of said signal, storing forensic tracer data in at least one of said non-volatile data stores; the method further including obfuscating said storage of said forensic tracer data so as to make detection thereof more difficult; wherein-the obfuscating comprises steganographically encoding the forensic tracer data amidst other data.

13

13. A method for robustly evidencing illicit use of a device, the device having associated therewith at least one data processor and at least one non-volatile data store, the method comprising: receiving a signal indicating possible use of the device for an illicit activity; in response to receipt of said signal, storing forensic tracer data in at least one of said non-volatile data stores; the method further including obfuscating said storage of said forensic tracer data so as to make detection thereof more difficult; wherein the obfuscating includes queuing the forensic tracer data in RAM for later storage, and later storing the data in said non-volatile store, wherein program tracing tools will note an immediate write of said forensic tracer data to the non-volatile store.

14

14. The method of claim 13 wherein said device is a scanner.

15

15. The method of claim 13 wherein said device is a printer.

16

16. A method for robustly evidencing illicit use of a device, the device having associated therewith at least one data processor and at least one non-volatile data store, the method comprising: receiving a signal indicating possible use of the device for an illicit activity; in response to receipt of said signal, storing forensic tracer data in at least one of said non-volatile data stores; the method further including obfuscating said storage of said forensic tracer data so as to make detection thereof more difficult, later performing an integrity check of the obfuscated forensic tracer data, and repairing any damage found.

17

17. The method of claim 16 wherein said device is a scanner.

18

18. The method of claim 16 wherein said device is a printer.

19

19. A method for robustly evidencing illicit use of a device, the device having associated therewith at least one data processor and at least one non-volatile data store, the method comprising: receiving a signal indicating possible use of the device for an illicit activity; in response to receipt of said signal, storing forensic tracer data in at least one of said non-volatile data stores; the method further including obfuscating said storage of said forensic tracer data so as to make detection thereof more difficult, and replicating obsfuscated storage of said forensic tracer data at several storage locations.

20

20. The method of claim 19 wherein said device is a scanner.

21

21. The method of claim 19 wherein said device is a printer.

22

22. A method for robustly evidencing illicit use of a device, the device having associated therewith at least one data processor and at least one non-volatile data store, the method comprising: receiving a signal indicating possible use of the device for an illicit activity; in response to receipt of said signal, storing forensic tracer data in at least one of said non-volatile data stores; the method further including obfuscating said storage of said forensic tracer data so as to make detection thereof more difficult; wherein the obfuscating comprises steganographically encoding the forensic tracer data amidst other data.

23

23. The method of claim 22 wherein said device is a scanner.

24

24. The method of claim 22 wherein said device is a printer.

Classification Codes (CPC)

Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.

Patent Metadata

Filing Date

November 3, 1998

Publication Date

April 15, 2003

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “Methods for evidencing illicit use of a computer system or device” (US-6549638). https://patentable.app/patents/US-6549638

© 2026 Patentable. All rights reserved.

Patentable is a research and drafting-assistant tool, not a law firm, and does not provide legal advice. Documents we generate are drafts for review by a licensed patent attorney.